Model Context Protocol
| Developed by | Anthropic |
|---|---|
| Introduced | November25, 2024;22 months ago(2024年11月25日) |
| Industry | Artificial intelligence |
| Connector type | |
| Website | modelcontextprotocol |
The Model Context Protocol (MCP) is an open standard and open-source framework introduced by Anthropic in November 2024 to standardize the way artificial intelligence (AI) systems like large language models (LLMs) integrate and share data with external tools, systems, and data sources.[1] MCP provides a standardized interface for reading files, executing functions, and handling contextual prompts.[2] Following its announcement, the protocol was adopted by major AI providers, including OpenAI and Google DeepMind.[3] [4] In December 2025, Anthropic donated MCP to the Agentic AI Foundation, a fund under the Linux Foundation.
Background
[edit ]MCP was announced by Anthropic in November 2024 as an open standard [5] for connecting AI assistants to data systems such as content repositories, business management tools, and development environments.[6] The protocol was created at Anthropic by engineers David Soria Parra and Justin Spahr-Summers.[6] MCP was designed to address information silos and legacy systems.[6] Before MCP, developers often had to build custom connectors for each data source or tool, resulting in what Anthropic described as an "×ばつM" data integration problem.[6] [7]
Earlier approaches such as OpenAI's 2023 "function-calling" API and the ChatGPT plug-in framework—solved similar problems but required vendor-specific connectors.[7] MCP reuses the message-flow ideas of the Language Server Protocol (LSP).[8]
In December 2025, Anthropic donated MCP to the Agentic AI Foundation (AAIF), a directed fund under the Linux Foundation, co-founded by Anthropic, Block and OpenAI, with support from other companies.[9] Later that month, Anthropic also published Agent Skills, a companion open standard for packaging task-specific instructions and resources that AI agents load on demand.[10]
Features
[edit ]MCP defines a standardized framework for integrating AI systems with external data sources and tools.[2] Applications include querying structured databases in plain language.[8]
The protocol distinguishes between MCP hosts, MCP clients and MCP servers. An MCP host is typically an AI agent that interacts with an LLM and requires services from one or more MCP servers. For each of these MCP servers, the MCP host will create a dedicated MCP client that communicates with that server. Client and host will typically run on the same machine, while the MCP servers may be local or remote.[11]
Each server provides one or more tools or resources. Tools might include database access, calculators, or access to code or repositories; a resource might be a document such as an FAQ. The MCP client asks its server for a list of tools and resources the server provides; the server replies with a natural-language description of the capabilities of each tool and the expected format to call the tool. This information is given to the LLM; if the LLM requires the services of one of these tools, the MCP host will instruct the relevant MCP client to call the tool. The MCP server performs the tool action and returns the results, which the MCP host then injects into the LLM conversation.[11] Client and server communicate using the JSON-RPC 2.0 messages.[8]
The protocol was released with software development kits (SDKs) in programming languages including Python, TypeScript, C# and Java and examples of MCP server implementations.[8] [12]
The protocol is used in AI-assisted software development tools. Integrated development environments (IDEs), coding platforms such as Replit, and code intelligence tools like Sourcegraph have adopted MCP to grant AI coding assistants real-time access to project context.[5]
MCP Apps is an official extension to the Model Context Protocol built on mcp-ui. While the base MCP specification is restricted to text and structured data, MCP Apps standardizes the delivery of interactive user interfaces—such as dashboards, forms, and data visualizations—from MCP servers to host applications like Claude and ChatGPT.[13]
Adoption
[edit ]In March 2025, OpenAI officially adopted the MCP, after having integrated the standard across its products, including the ChatGPT desktop app.[3] [2] In September 2025, OpenAI added support for MCP to ChatGPT apps. This allows for third-party access inside ChatGPT.[14]
MCP can be integrated with Microsoft Semantic Kernel, and Azure OpenAI.[15] MCP servers can be deployed to Cloudflare.[16]
In April 2026, the AAIF held the MCP Dev Summit North America in New York City, drawing approximately 1,200 attendees.[17] That same month, Salesforce's Headless 360 platform began routing customer and agent interactions via MCP; in late May, Salesforce reported 4.5 million MCP calls had been processed since launch.[18] [19]
By mid-2026, more than 10,000 MCP servers had reportedly been deployed in production, with the protocol's SDKs downloaded over 97 million times per month.[20]
2026年07月28日 revision
[edit ]On July 28, 2026, MCP's maintainers finalized a major revision of the specification, described by Anthropic technical staff member David Soria Parra as the most substantial change to the protocol since the addition of authorization.[20] The revision removes protocol-level session tracking, making MCP stateless at the protocol layer: information about protocol version, client identity, and capabilities is instead carried in a _meta parameter with each request.[20] The change brings MCP's request model closer to that of Anthropic's own Claude Messages API.[20]
The revision also deprecated several features that had seen limited use, including sampling (allowing a server to request a completion from the client's model) and roots (allowing clients to indicate relevant file-system locations to a server); deprecated features remain functional for a minimum of twelve months.[20] Some previously core functionality, such as the Tasks feature for long-running operations, was moved out of the base protocol and into optional extensions.[20] Not all of the changes are backward compatible, and servers implementing the new revision may not interoperate with older clients without a compatibility layer.[20]
Security risks and vulnerabilities
[edit ]MCP has been subject to several security vulnerabilities, both in how models handle tool calling and in MCP software itself.
In April 2025, Invariant Labs described "tool poisoning attacks" in which malicious instructions are hidden in MCP tool descriptions that the AI model can read but users cannot see.[21] The vulnerability comes from the assumption that tool descriptions are trustworthy. These problems are not specific to MCP and can occur whenever an LLM has access to tools with untrusted input. Tool poisoning is a form of prompt injection.[22]
Several vulnerabilities have also been found in MCP software itself. In July 2025, JFrog disclosed CVE-2025-6514, a critical flaw (CVSS 9.6) in mcp-remote, a tool that connects MCP clients to remote servers. The flaw allowed a malicious server to run arbitrary commands on the user's machine.[23] The vulnerability affected versions 0.0.5 through 0.1.15 and was fixed in version 0.1.16.[23] Around the same time, researchers reported CVE-2025-49596 in Anthropic's MCP Inspector developer tool. Because the Inspector required no authentication by default, attackers could use it to run code on a user's computer.[24]
The MCP specification has since added security requirements. The specification now requires implementations to follow OAuth 2.1 security best practices.[25] Its security guidance describes "confused deputy" risks in MCP proxy servers and states that token passthrough is forbidden.[25] In a May 2026 report, the U.S National Security Agency stated that MCP's "rapid proliferation has outpaced the development of its security model".[26]
Reception
[edit ]The Verge reported that MCP addresses a growing demand for AI agents that are contextually aware and capable of pulling from diverse sources.[5]
MCP has been likened to OpenAPI, a similar specification that aims to describe APIs.[27] [28]
See also
[edit ]- Agent2Agent – Open protocol for communication between AI agents
- AI governance
- Application programming interface – Connection between computers or programsPages displaying short descriptions of redirect targets
- LangChain – Language model application development framework
- Machine learning – Subset of artificial intelligence
- Open weights
- Software agent – Computer program acting for a user
- Retrieval-augmented generation
References
[edit ]- ↑ David, Emilia (November 25, 2024). "Anthropic releases Model Context Protocol to standardize AI-data integration". VentureBeat . Retrieved 2025年05月12日.
- 1 2 3 Kumar, Vinay (March 26, 2025). "The open source Model Context Protocol was just updated — here's why it's a big deal". VentureBeat . Retrieved 2025年05月12日.
- 1 2 Wiggers, Kyle (March 25, 2025). "OpenAI adopts rival Anthropic's standard for connecting AI models to data". TechCrunch.
- ↑ Wiggers, Kyle (April 9, 2025). "Google to embrace Anthropic's standard for connecting AI models to data". TechCrunch. Retrieved 2025年05月12日.
- 1 2 3 Roth, Emma (November 25, 2024). "Anthropic launches tool to connect AI systems directly to datasets". The Verge.
- 1 2 3 4 "Introducing the Model Context Protocol". Anthropic. November 25, 2024. Retrieved 2025年05月12日.
- 1 2 Edwards, Benj (1 April 2025). "MCP: The new "USB-C for AI" that's bringing fierce rivals together". Ars Technica. Retrieved 2025年05月24日.
- 1 2 3 4 Ouellette, Michael (2025年05月09日). "Model context protocol: the next big step in generating value from AI". Engineering.com. Retrieved 2025年06月23日.
- ↑ Bellan, Rebecca (2025年12月09日). "OpenAI, Anthropic, and Block join new Linux Foundation effort to standardize the AI agent era". TechCrunch. Retrieved 2025年12月10日.
- ↑ Deutscher, Maria (2025年12月18日). "Anthropic makes agent Skills an open standard". SiliconANGLE. Retrieved 2026年08月12日.
- 1 2 "Architecture overview". Model Context Protocol. Retrieved 2026年06月22日.
- ↑ "Model Context Protocol". GitHub. Retrieved 2025年06月20日.
- ↑ "MCP Apps, the Model Context Protocol's first official extension, turns AI responses into interactive interfaces". the decoder. 2026年01月26日. Archived from the original on 2026年01月26日.
- ↑ "OpenAI adds 'powerful but dangerous' support for MCP in ChatGPT dev mode". VentureBeat. September 11, 2025. Retrieved 2026年04月09日.
- ↑ "Using the Model Context Protocol in Azure and beyond". InfoWorld. 2025年05月01日. Retrieved 2026年06月14日.
- ↑ "Cloudflare Outlines MCP Architecture as Enterprises Confront Security and Governance Risks". InfoQ. 2026年04月22日. Retrieved 2026年06月14日.
- ↑ "AAIF's MCP Dev Summit: Gateways, gRPC, and Observability Signal Protocol Hardening". InfoQ. 2026年04月14日. Retrieved 20 April 2026.
- ↑ Johnson, O'Ryan (28 May 2026). "Salesforce waves bye-bye to UI in 'headless' embrace". The Register. Retrieved 9 July 2026.
- ↑ Martin, Henry (15 April 2026). "Salesforce Headless 360 and Agentforce Vibes 2.0 Revealed at TDX 2026". Salesforce Ben. Retrieved 9 July 2026.
- 1 2 3 4 5 6 7 Jackson, Joab (23 July 2026). "Model Context Protocol prepares to break with its stateful past". The Register . Retrieved 20 August 2026.
- ↑ Beurer-Kellner, Luca; Fischer, Marc (2025年04月01日). "MCP Security Notification: Tool Poisoning Attacks". invariantlabs.ai. Retrieved 2026年10月02日.
- ↑ Willison, Simon (2025年04月09日). "Model Context Protocol has prompt injection security problems". Simon Willison’s Weblog. Retrieved 2026年10月02日.
- 1 2 "Critical RCE Vulnerability in mcp-remote: CVE-2025-6514 Threatens LLM Clients". jfrog.com. 2025年07月09日. Retrieved 2026年10月02日.
- ↑ Ravie, Lakshmanan (2025年07月10日). "Critical mcp-remote Vulnerability Enables Remote Code Execution, Impacting 437,000+ Downloads". The Hacker News. Retrieved 2026年10月02日.
- 1 2 "Security Best Practices". Model Context Protocol. Retrieved 2026年10月02日.
- ↑ "Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation" (PDF). National Security Agency. May 2026.
- ↑ MacManus, Richard (13 March 2025). "MCP: The Missing Link Between AI Agents and APIs". The New Stack. Retrieved 29 May 2025.
- ↑ Fanelli, Alessio. "Why MCP Won". www.latent.space. Retrieved 29 May 2025.
Further reading
[edit ]- Hou, Xinyi; Zhao, Yanjie; Wang, Shenao; Wang, Haoyu (2025). "Model Context Protocol (MCP): Landscape, Security Threats, and Future Research Directions". arXiv:2503.23278 [cs.CR].
- Edwards, Benj (April 1, 2025). "MCP: The new "USB-C for AI" that's bringing fierce rivals together". Ars Technica.
- Jackson, Fiona (March 28, 2025). "OpenAI Agents Now Support Rival Anthropic's Protocol, Making Data Access 'Simpler, More Reliable'". TechRepublic.